[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247974

 
 

909

 
 

194654

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2008-0454Date: (C)2008-01-24   (M)2023-12-22


Cross-zone scripting vulnerability in the Internet Explorer web control in Skype 3.6.0.244, and earlier 3.5.x and 3.6.x versions, on Windows allows user-assisted remote attackers to inject arbitrary web script or HTML in the Local Machine Zone via the Title field of a (1) Dailymotion and possibly (2) Metacafe movie in the Skype video gallery, accessible through a search within the "Add video to chat" dialog, aka "videomood XSS."

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 9.3
Exploit Score: 8.6
Impact Score: 10.0
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: MEDIUM
Authentication: NONE
Confidentiality: COMPLETE
Integrity: COMPLETE
Availability: COMPLETE
  
Reference:
http://www.securityfocus.com/archive/1/archive/1/486512/100/0/threaded
http://archives.neohapsis.com/archives/fulldisclosure/2008-01/0363.html
http://archives.neohapsis.com/archives/fulldisclosure/2008-01/0337.html
BID-27338
ADV-2008-0194
VU#248184
http://aviv.raffon.net/2008/01/17/SkypeCrosszoneScriptingVulnerability.aspx
http://share.skype.com/sites/security/2008/01/skype_cross_zone_scripting_vul.html
http://skype.com/security/skype-sb-2008-001-update1.html
http://skype.com/security/skype-sb-2008-001.html
http://www.critical.lt/?opinions/show/1470
http://www.gnucitizen.org/blog/vulnerabilities-in-skype
skype-addvideotochat-code-execution(39754)

CPE    1
cpe:/a:microsoft:ie
CWE    1
CWE-79
OVAL    1
oval:org.secpod.oval:def:9526

© SecPod Technologies